CN105208072A - Remote control method and device of virtual switch - Google Patents

Remote control method and device of virtual switch Download PDF

Info

Publication number
CN105208072A
CN105208072A CN201510479116.2A CN201510479116A CN105208072A CN 105208072 A CN105208072 A CN 105208072A CN 201510479116 A CN201510479116 A CN 201510479116A CN 105208072 A CN105208072 A CN 105208072A
Authority
CN
China
Prior art keywords
virtual switch
port
connection
listening
client
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201510479116.2A
Other languages
Chinese (zh)
Other versions
CN105208072B (en
Inventor
李岩
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Hangzhou Dt Dream Technology Co Ltd
Original Assignee
Hangzhou Dt Dream Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Hangzhou Dt Dream Technology Co Ltd filed Critical Hangzhou Dt Dream Technology Co Ltd
Priority to CN201510479116.2A priority Critical patent/CN105208072B/en
Publication of CN105208072A publication Critical patent/CN105208072A/en
Application granted granted Critical
Publication of CN105208072B publication Critical patent/CN105208072B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/02Protocols based on web technology, e.g. hypertext transfer protocol [HTTP]
    • H04L67/025Protocols based on web technology, e.g. hypertext transfer protocol [HTTP] for remote control or remote monitoring of applications
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/10Protocols in which an application is distributed across nodes in the network

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer And Data Communications (AREA)

Abstract

The invention provides a remote control method and device of a virtual switch. The method comprises that a cloud management platform establishes connection to the target virtual machine via a first monitoring port, and stores the mapping relation between the established connection and the IP address of the target virtual machine locally; the cloud management platform establishes connection to a client via a second monitoring port, the number of a third monitoring port and the IP address of the target virtual switch which are sent by the client are received on the basis of the connection, and the third monitoring port is started in the client locally; and the mapping relation is inquired to obtain connection corresponding to the received IP address of the target virtual machine, the number of the third monitoring port is forwarded to the target virtual machine via the connection, so that the target virtual machine initiates establishment of control connection to the client based on the number of the third monitoring port, and receives a remote control instruction emitted by the client via the established control connection. The remote control method and device can improve the network safety level.

Description

The long-range control method of virtual switch and device
Technical field
The application relates to the communications field, particularly relates to a kind of long-range control method and device of virtual switch.
Background technology
Increasing cloud management platform is passed through at Hypervisor deploy vSwitch (virtual switch), and the resources of virtual machine towards bottom provides Exchange Service.By the support OpenFlow agreement that vSwitch can be very perfect, and vSwitch usually understands user oriented and provides client utility, and user, by this client utility, can carry out Long-distance Control to the vSwitch on Hypervisor.
In existing realization, when user carries out Long-distance Control by the client utility that vSwitch user oriented provides to the vSwitch on Hypervisor, normally by enabling port listening service on the Daemon (finger daemon) of vSwitch, connected by the port on monitoring Hypervisor and client, then realize Long-distance Control based on this connection of setting up.
Visible, between vSwitch and client, establishment of connection depends on the port monitored on Hypervisor, and therefore in the process of connection establishment, the fire compartment wall on Hypervisor then needs to decontrol port and monitors restriction, may bring the hidden danger in safety.
Summary of the invention
The application proposes a kind of long-range control method of virtual switch, be applied to cloud management platform, described cloud management platform enables the first listening port and the second listening port in advance, the connection establishment request that wherein said first listening port is initiated for receiving virtual switch, the connection establishment request that described second listening port is initiated for receiving client, the method comprises:
Connected by described first listening port and object virtual switch, and preserve the mapping relations between connection and the IP address of described object virtual switch set up in this locality;
Connected by described second listening port and client, and receive the port numbers of the 3rd listening port of enabling in its this locality and the IP address of object virtual switch of the transmission of described client based on this connection;
Inquire about described mapping relations and obtain the connection corresponding with the IP address of the described object virtual switch received, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, to make described object virtual switch initiate to set up control connection to described client based on the port numbers of described 3rd listening port, and the control connection passing through to have set up receives the remote control commands that described client sends.
Optionally, the connection between described first listening port and described virtual switch is long connection; Remain connection status in the life cycle that described length is connected to the virtual switch of its correspondence always.
Optionally, described method also comprises:
After connection between arbitrary virtual switch and described first listening port disconnects, according to the connection establishment request that this virtual switch is initiated within a preset time interval again, re-establish this connection.
The application also proposes a kind of long-range control method of virtual switch, is applied to client, and the method comprises:
When receiving the remote control commands for object virtual switch of user's input, at local boot port listening service;
After described port listening service has started, the second listening port enabled in advance with described cloud management platform connects, and the port numbers of the 3rd listening port of being enabled by described port listening service by this connection and the IP address of object virtual switch send to described cloud management platform, to make described cloud management platform, the port numbers of described 3rd listening port are transmitted to described object virtual switch;
The control connection between described object virtual switch is set up in the control connection request of setting up that the described object virtual switch received based on described 3rd listening port is initiated, and described remote control commands is sent to described object virtual switch by this control connection.
Optionally, described method also comprises:
When described remote control commands sends to described object virtual switch by described control connection, and after receiving the execution result of described object virtual switch, close the described port listening service started, and discharge the control connection between described 3rd listening port and described object virtual switch.
The application also proposes a kind of remote control of virtual switch, be applied to cloud management platform, described cloud management platform enables the first listening port and the second listening port in advance, the connection establishment request that wherein said first listening port is initiated for receiving virtual switch, the connection establishment request that described second listening port is initiated for receiving client, this device comprises:
Setting up module, for being connected by described first listening port and object virtual switch, and preserving the mapping relations between connection and the IP address of described object virtual switch set up in this locality;
Receiver module, for being connected by described second listening port and client, and receives the port numbers of the 3rd listening port of enabling in its this locality and the IP address of object virtual switch of the transmission of described client based on this connection;
Forwarding module, the connection corresponding with the IP address of the described object virtual switch received is obtained for inquiring about described mapping relations, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, to make described object virtual switch initiate to set up control connection to described client based on the port numbers of described 3rd listening port, and the control connection passing through to have set up receives the remote control commands that described client sends.
Optionally, the connection between described first listening port and described virtual switch is long connection; Remain connection status in the life cycle that described length is connected to the virtual switch of its correspondence always.
Optionally, described module of setting up is further used for:
After connection between arbitrary virtual switch and described first listening port disconnects, according to the connection establishment request that this virtual switch is initiated within a preset time interval again, re-establish this connection.
The application also proposes a kind of remote control of virtual switch, is applied to client, and this device comprises:
Start module, for when receiving the remote control commands for object virtual switch of user's input, at local boot port listening service;
First sending module, for after described port listening service has started, the second listening port enabled in advance with described cloud management platform connects, and the port numbers of the 3rd listening port of being enabled by described port listening service by this connection and the IP address of object virtual switch send to described cloud management platform, to make described cloud management platform, the port numbers of described 3rd listening port are transmitted to described object virtual switch;
Second sending module, the control connection initiated for the described object virtual switch received based on described 3rd listening port sets up the control connection of asking between foundation with described object virtual switch, and described remote control commands is sent to described object virtual switch by this control connection.
Optionally, described device also comprises:
Closing module, for after described remote control commands sends to described object virtual switch based on described control connection, close the described port listening service started, and discharge the control connection between described 3rd listening port and described object virtual switch.
In the application, connected based on the first listening port enabled and object virtual switch by cloud management platform, and preserve the mapping relations between connection and the IP address of described object virtual switch set up in this locality, connect based on the second listening port enabled and client, client is sent in the port numbers of the 3rd listening port and the IP address of object virtual switch of enabling its this locality to cloud management platform by this connection, cloud management platform receive client send the port numbers of the 3rd listening port and the IP address of object virtual switch after, the connection that query mappings Relation acquisition is corresponding with the IP address of the object virtual switch received, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, initiated to set up control connection to described client by the port numbers of object virtual switch based on the 3rd listening port, after control connection has been set up, client sends remote control commands by this control connection to object virtual switch, Long-distance Control is carried out to object virtual switch.During owing to setting up control connection between client and object virtual switch, no longer need to enable port listening service on object virtual switch, and the foundation of control connection is initiatively initiated by object virtual switch slave firewall is inner, therefore the port of open Hypervisor is no longer needed to monitor restriction, and the protection rule of amendment object virtual switch side fire compartment wall, thus improve the fail safe of network.
Accompanying drawing explanation
Fig. 1 is a kind of cloud management platform networking diagram that the application one embodiment provides;
Fig. 2 is the flow chart of the long-range control method of a kind of virtual switch that the application one embodiment provides;
Fig. 3 is the logic diagram of the remote control of a kind of virtual switch that the application one embodiment provides;
Fig. 4 is the server of remote control or the hardware structure diagram of server cluster of the described virtual switch of carrying that the application one embodiment provides;
Fig. 5 is the logic diagram of the remote control of a kind of virtual switch that the application one embodiment provides;
Fig. 6 is the server of cloud management platform this locality or the hardware structure diagram of third party's main frame of the remote control of the described virtual switch of carrying that the application one embodiment provides.
Embodiment
In existing realization, user, when the client utility using virtual switch user oriented to provide carries out Long-distance Control to object virtual switch, needs its enable port monitoring service on object virtual switch usually.
In the networking of existing cloud management platform, cloud management platform is in order to carry out flexible management and deployment to existing resources of virtual machine more flexibly, usual needs dispose vSwitch (can be understood as and simulate corresponding vSwitch by installing vSwitchDaemon in Hypervisor layer) respectively by installing vSwitchDaemon in the Hypervisor layer of each virtual machine, provide Exchange Service towards the resources of virtual machine of bottom.
After vSwitch has disposed, can on vSwitchDaemon its enable port monitoring service, monitor the listening port in Hypervisor layer by SwitchDaemon, process the connection establishment request of client.Client is when initiating to connect to vSwitch, can using this listening port as destination interface, the three-way handshake of a TCP is carried out with vSwitchDaemon, when after three-way handshake, connection establishment completes, Client-initiated remote control commands is sent to vSwitchDaemon by this connection by client, and result is returned to client by this connection by vSwitchDaemon after processing is completed, and a Long-distance Control so far for object vSwitch completes alternately.
In above technical scheme, on the one hand, due to needs its enable port monitoring service on vSwitchDaemon, therefore Hypervisor must allow vSwitchDaemon can monitor its port, but most of Hypervisor acquiescence can exist port monitoring restriction, therefore open port listening service to vSwitchDaemon and bring difficulty.On the other hand, due to needs its enable port monitoring service on vSwitchDaemon, therefore the fire compartment wall of Hypervisor must be let pass all messages of above-mentioned listening port as destination interface, therefore has to modify to the protection rule of the fire compartment wall of Hypervisor.
For above-mentioned first aspect, port can be decontroled by the safe class reducing Hypervisor and monitor restriction, but decontrol port monitoring restriction, certain potential safety hazard can be there is, some rogue programs may be caused on Hypervisor to create service.For above-mentioned second aspect, because the protection rule revising fire compartment wall is usually more loaded down with trivial details, be therefore unfavorable for very much carrying out automation deployment and management to the resources of virtual machine in networking.
For solving the problem, the application proposes a kind of long-range control method of virtual switch, by enabling the first listening port and the second listening port in advance in cloud management platform, cloud management platform connects based on the first listening port enabled and object virtual switch, and preserves the mapping relations between connection and the IP address of described object virtual switch set up in this locality, connect based on the second listening port enabled and client, client is sent in the port numbers of the 3rd listening port and the IP address of object virtual switch of enabling its this locality to cloud management platform by this connection, cloud management platform receive client send the port numbers of the 3rd listening port and the IP address of object virtual switch after, the connection that query mappings Relation acquisition is corresponding with the IP address of the object virtual switch received, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, initiated to set up control connection to described client by the port numbers of object virtual switch based on the 3rd listening port, after control connection has been set up, client sends remote control commands by this control connection to object virtual switch, Long-distance Control is carried out to object virtual switch.During owing to setting up control connection between client and object virtual switch, no longer need to enable port listening service on object virtual switch, and the foundation of control connection is initiatively initiated by object virtual switch slave firewall is inner, therefore the port of open Hypervisor is no longer needed to monitor restriction, and the protection rule of amendment object virtual switch side fire compartment wall, thus improve the fail safe of network.
The application to be described in conjunction with concrete application scenarios below by specific embodiment.
Please refer to Fig. 1, Fig. 1 is the long-range control method of a kind of virtual switch that the application one embodiment provides, and the executive agent of the method can be cloud management platform and client, and wherein, cloud management platform can be server or server cluster; The user oriented that client can be mounted on the server of cloud management platform this locality or third party's main frame provides the client-side program carrying out Long-distance Control for object virtual switch; Described cloud management platform enables the first listening port and the second listening port in advance, the connection establishment request that described first listening port is initiated for receiving virtual switch, the connection establishment request that described second listening port is initiated for receiving client.
Cloud management platform and client cooperatively interact, and perform following methods:
Step 101, cloud management platform is connected by the first listening port and object virtual switch, and preserves the mapping relations between connection and the IP address of described object virtual switch set up in this locality; Step 102, cloud management platform is connected by described second listening port and client, and client is sent in the port numbers of the 3rd listening port and the IP address of object virtual switch of enabling its this locality to cloud management platform based on this connection;
Step 103, when cloud management platform receive client send the port numbers of the 3rd listening port and the IP address of object virtual switch after, inquire about described mapping relations and obtain the connection corresponding with the IP address of the object virtual switch received, and by this connection, the port numbers of the 3rd listening port is transmitted to object virtual switch, initiate to set up control connection to described client based on the port numbers of described 3rd listening port to make object virtual switch, client sends remote control commands by the control connection set up to this object virtual switch, Long-distance Control is carried out to this object virtual switch.
In the present embodiment, the vSwitchDaemon on Hypervisor can no longer its enable port monitoring service, the substitute is, can open an agency service in cloud management platform.
This agency service can comprise enables two ports that can be used for monitoring in advance; Such as, cloud management platform can specify two ports that can be used for monitoring from available port resource, respectively as the first listening port and the second listening port.This first listening port may be used for the connection establishment request receiving vSwitch initiation, and this second listening port may be used for the connection establishment request receiving client initiation.
Wherein, for security consideration, the port numbers of this first listening port can shift to an earlier date static configuration on each Hypervisor as the configuration information of each vSwitch; The port numbers of this second listening port also can shift to an earlier date static configuration in the client of user side as the configuration information of client.Certainly, in actual applications, for the network environment that fail safe is higher, cloud management platform is after enabling the first listening port and the second listening port, also message interaction be can carry out with each vSwitch disposed and client respectively, by the mode of message interaction, the port numbers of the first listening port enabled and the second listening port each vSwitch and client are advertised to respectively.
In vSwitch side, when vSwitch is deployed on each Hypervisor by cloud management platform respectively, and vSwitchDaemon all installs and after having started on each Hypervisor, now each vSwitch can according to the port numbers of the first pre-configured listening port, initiatively initiate TCP to cloud management platform to connect, when cloud management platform is by monitoring first listening port, after receiving the TCP connection establishment request of each vSwitch initiation, TCP can be set up with each vSwitch respectively by the three-way handshake of TCP and be connected.After TCP connection establishment between each vSwitch completes, each TCP that cloud management platform can have been set up in this locality preservation connects the mapping relations between the IP address (i.e. the IP address of Hypervisor belonging to this vSwitch) of opposite end vSwitch.
Wherein, what deserves to be explained is, the TCP that sets up between cloud management platform and vSwitch connects and is long connection, remains connection status in the life cycle that this length is connected to the vSwitch of its correspondence always.TCP between arbitrary vSwitch with cloud management platform is connected due to after congested, fault or other reason disconnect, this vSwitch can within the time interval of presetting (such as every 10 seconds), again the first listening port to cloud management platform initiates the request of TCP connection establishment, has re-established until this TCP connects.In this way, the TCP that can ensure between cloud service platform with each vSwitch is connected and does not interrupt.
In client side, user can by editing corresponding remote control command in the client, and any object vSwitch in each vSwitch disposed cloud management platform carries out Long-distance Control.Such as, the title of each vSwitch that cloud management platform can have been disposed by client and IP address present to user in the form of a list in the visible user interface of client, user can select corresponding object vSwitch in the list, then carries out Long-distance Control by the remote control command that editor is corresponding to this object vSwitch selected.When client receives the remote control command of user's input, at local boot port listening service, and the 3rd listening port can be bound.Wherein, the 3rd listening port can not be designated port.
Such as, client is when local boot port listening service, can to operating system application listening port, operating system can be client Random assignment port in available port current from system, after client obtains this port, can start monitoring service on that port, subsequent client by monitoring this port, can receive the control connection foundation request that object vSwitch initiates.
When client at local boot port listening service, and after having bound the 3rd listening port, can according to the port numbers of the second pre-configured listening port, initiatively initiate TCP to cloud management platform to connect, when cloud management platform is by monitoring second listening port, after receiving the TCP connection establishment request of client initiation, TCP can be set up by the three-way handshake of TCP and client and be connected.After TCP connection establishment between client completes, client can be connected the port numbers of the 3rd listening port of binding by this TCP set up, and user wants the IP address of the object vSwitch carrying out Long-distance Control to send to cloud management platform.
After cloud management platform receives the port numbers of the 3rd listening port and the IP address of above-mentioned purpose vSwitch that client sends, corresponding with this object vSwitch longly to connect can be obtained by inquiring about local above-mentioned mapping relations of preserving.When inquire corresponding with this object vSwitch long connect after, the long connection that the port numbers of the 3rd listening port received is inquired by this can be sent to this object vSwitch.
After this object vSwitch receives the port numbers of the 3rd listening port that cloud management platform sends, initiatively can initiate TCP to client according to the port numbers of the 3rd listening port to connect, after client receives the TCP establishment of connection request of object vSwitch initiation by monitoring the 3rd listening port, set up TCP by three-way handshake with this object vSwitch to be connected, the TCP that now this foundation completes connects the control connection be between client and object vSwitch, the remote control commands that user can edit by client is sent on object vSwitch by this control connection.Object vSwitch, after receiving this remote control commands, performs this instruction, and execution result is returned to client by this control connection, is presented by user's visualization interface by client to user.
The remote control commands of user being edited when client sends to object vSwitch, and after receiving the execution result of object vSwitch, if the remote interaction now between user and object vSwitch completes, the described port listening service started can be closed by client, stop proceeding to monitor for described 3rd listening port, and the 3rd control connection set up between listening port and object vSwitch is discharged.Wherein, when user needs to carry out Long-distance Control by client to other object vSwitch, above process can be repeated, repeat no more.
Known by describing above, client and object vSwitch are in the process connected, object vSwitch is its enable port monitoring service no longer, but carry out its enable port monitoring service by client, and by the port numbers of the listening port of binding, be transmitted to object vSwitch by the agency service of cloud management platform.Thus, object vSwitch can according to the port numbers of the listening port of the client binding received, slave firewall inner initiatively initiate to set up control connection to client, initiator due to this control connection is positioned at fire compartment wall inside, therefore in the process setting up control connection, set up the mutual message produced in the process of control connection can normally by fire compartment wall, and not need to modify to the protection rule of fire compartment wall.And, due to object vSwitch no longer its enable port monitoring service, therefore also no longer need the port of open Hypervisor to monitor restriction.Visible, in this way, the fail safe of networking can be improved.
Be described below by way of the concrete technical scheme of application example to above embodiment.
Refer to Fig. 2, Fig. 2 is a kind of cloud management platform networking diagram shown in the present embodiment.
As shown in Figure 2, suppose that cloud management platform deploys vSwitch1 and vSwitch2 respectively in networking.
In the agency service that cloud management platform is opened, the port numbers of two listening ports enabled in advance is respectively 62121 and 62122, is designated as Port1 and Port2 respectively.The connection request that Port1 initiates for receiving vSwitch1 and vSwitch2; The connection request that Port2 initiates for receiving client.
After client enables port listening service, the listening port of binding is Port3.
In vSwitch side:
VSwitch1 with vSwitch2 initiatively initiates TCP to cloud management platform according to the port numbers 62121 of the Port1 of configuration and is connected, after cloud management platform receives by listening port numbers 62121 the TCP connection establishment request that vSwitch1 and vSwitch2 initiate, carry out three-way handshake respectively with vSwitch1 and vSwitch2 and set up TCP and be connected C1 and C2; Wherein connect C1 with C2 and remain long connection.
Meanwhile, cloud management platform connects in this locality the IP address of C1 and vSwitch1, and the mapping relations between the IP address connecting C2 and vSwitch2.
In client side:
On the one hand, client terminal start-up port listening service, and bind listening port Port3.
On the other hand, client is initiatively initiated TCP to cloud management platform according to the port numbers 62122 of the Port2 of configuration and is connected, after cloud management platform receives by listening port numbers 62122 the TCP connection establishment request that client initiates, carry out three-way handshake with client and set up TCP and be connected C3.
The title of vSwitch1 and vSwitch2 and IP address can present to user by client in the form of a list in visible user interface, and user can select object vSwitch to carry out Long-distance Control in the list.Suppose that user selects to carry out Long-distance Control to vSwitch1, client can by the port numbers of listening port Port3 of binding, and the IP address of vSwitch1 sends to cloud management platform by connection C3.
After cloud management platform receives the IP address of vSwitch1 and the port numbers of Port3, first in the mapping relations set up, find out long connection C1 corresponding to vSwitch1 according to the IP address of vSwitch1, then the port numbers of Port3 is sent to vSwitch1 by the long C1 that connects.
After vSwitch1 receives the port numbers of Port3, initiatively can initiate to set up control connection C4 to client according to this port numbers, because vSwitch1 is positioned at fire compartment wall inside, therefore set up in initiation the mutual message produced in the process of control connection C4 and normally by fire compartment wall, and can not need amendment protection rule.
After this control connection C4 has set up, the remote control commands that user can edit by client sends to vSwitch1 by this control connection C4, after vSwitch1 receives this remote control commands, this instruction can be performed, and execution result is returned to client by this control connection C4.Since then, a Long-distance Control of user and vSwitch1 completes alternately.
In the embodiment above, by enabling the first listening port and the second listening port in advance in cloud management platform, cloud management platform connects with object virtual switch respectively based on the first listening port enabled, and preserves the mapping relations between connection and the IP address of described object virtual switch set up in this locality, connect based on the second listening port enabled and client, client is sent in the port numbers of the 3rd listening port and the IP address of object virtual switch of enabling its this locality to cloud management platform by this connection, cloud management platform receive client send the port numbers of the 3rd listening port and the IP address of object virtual switch after, the connection that query mappings Relation acquisition is corresponding with the IP address of the object virtual switch received, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, initiated to set up control connection to described client by the port numbers of object virtual switch based on the 3rd listening port, after control connection has been set up, client sends remote control commands by this control connection to object virtual switch, Long-distance Control is carried out to object virtual switch.During owing to setting up control connection between client and object virtual switch, no longer need to enable port listening service on object virtual switch, and the foundation of control connection is initiatively initiated by object virtual switch slave firewall is inner, therefore the port of open Hypervisor is no longer needed to monitor restriction, and the protection rule of amendment object virtual switch side fire compartment wall, thus improve the fail safe of network.
Corresponding with said method embodiment, present invention also provides the embodiment of device.
Refer to Fig. 3, the application proposes a kind of remote control 30 of virtual switch, is applied to cloud management platform, and this cloud management platform can be server or server cluster; Described cloud management platform enables the first listening port and the second listening port in advance, the connection establishment request that wherein said first listening port is initiated for receiving virtual switch, the connection establishment request that described second listening port is initiated for receiving client; Wherein, refer to Fig. 4, as in the hardware structure involved by the server of remote control 30 of the described virtual switch of carrying or server cluster, generally include CPU, internal memory, nonvolatile memory, network interface and internal bus etc.; For software simulating, the remote control 30 of described virtual switch can be understood as the computer program be carried in internal memory usually, the logic device that the software and hardware formed after being run by CPU is combined, and described device 30 comprises:
Setting up module 301, for being connected by described first listening port and object virtual switch, and preserving the mapping relations between connection and the IP address of described object virtual switch set up in this locality;
Receiver module 302, for being connected by described second listening port and client, and receives the port numbers of the 3rd listening port of enabling in its this locality and the IP address of object virtual switch of the transmission of described client based on this connection;
Forwarding module 303, the connection corresponding with the IP address of the described object virtual switch received is obtained for inquiring about described mapping relations, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, to make described object virtual switch initiate to set up control connection to described client based on the port numbers of described 3rd listening port, and the control connection passing through to have set up receives the remote control commands that described client sends.
In the present embodiment, the connection between described first listening port and described virtual switch is long connection; Remain connection status in the life cycle that described length is connected to the virtual switch of its correspondence always.
In the present embodiment, described module 301 of setting up is further used for:
After connection between arbitrary virtual switch and described first listening port disconnects, according to the connection establishment request that this virtual switch is initiated within a preset time interval again, re-establish this connection.
Refer to Fig. 5, the application proposes a kind of remote control 50 of virtual switch, be applied to client, the user oriented that this client can be mounted on the server of cloud management platform this locality or third party's main frame provides the client-side program carrying out Long-distance Control for object virtual switch; Wherein, refer to Fig. 6, as in the hardware structure involved by the server of remote control 50 of the described virtual switch of carrying or local host, generally include CPU, internal memory, nonvolatile memory, network interface and internal bus etc.; For software simulating, the remote control 30 of described virtual switch can be understood as the computer program be carried in internal memory usually, the logic device that the software and hardware formed after being run by CPU is combined, and described device 50 comprises:
Start module 501, for when receiving the remote control commands for object virtual switch of user's input, at local boot port listening service;
First sending module 502, for after described port listening service has started, the second listening port enabled in advance with described cloud management platform connects, and the port numbers of the 3rd listening port of being enabled by described port listening service by this connection and the IP address of object virtual switch send to described cloud management platform, to make described cloud management platform, the port numbers of described 3rd listening port are transmitted to described object virtual switch;
Second sending module 503, the control connection initiated for the described object virtual switch received based on described 3rd listening port sets up the control connection of asking between foundation with described object virtual switch, and described remote control commands is sent to described object virtual switch by this control connection.
In the present embodiment, described device 50 also comprises:
Closing module 504, for after described remote control commands sends to described object virtual switch based on described control connection, close the described port listening service started, and discharge the control connection between described 3rd listening port and described object virtual switch.
Those skilled in the art, at consideration specification and after putting into practice invention disclosed herein, will easily expect other embodiment of the application.The application is intended to contain any modification of the application, purposes or adaptations, and these modification, purposes or adaptations are followed the general principle of the application and comprised the undocumented common practise in the art of the application or conventional techniques means.Specification and embodiment are only regarded as exemplary, and true scope and the spirit of the application are pointed out by claim below.
Should be understood that, the application is not limited to precision architecture described above and illustrated in the accompanying drawings, and can carry out various amendment and change not departing from its scope.The scope of the application is only limited by appended claim.
The foregoing is only the preferred embodiment of the application, not in order to limit the application, within all spirit in the application and principle, any amendment made, equivalent replacements, improvement etc., all should be included within scope that the application protects.

Claims (10)

1. the long-range control method of a virtual switch, be applied to cloud management platform, described cloud management platform enables the first listening port and the second listening port in advance, the connection establishment request that wherein said first listening port is initiated for receiving virtual switch, the connection establishment request that described second listening port is initiated for receiving client, it is characterized in that, the method comprises:
Connected by described first listening port and object virtual switch, and preserve the mapping relations between connection and the IP address of described object virtual switch set up in this locality;
Connected by described second listening port and client, and receive the port numbers of the 3rd listening port of enabling in its this locality and the IP address of object virtual switch of the transmission of described client based on this connection;
Inquire about described mapping relations and obtain the connection corresponding with the IP address of the described object virtual switch received, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, to make described object virtual switch initiate to set up control connection to described client based on the port numbers of described 3rd listening port, and the control connection passing through to have set up receives the remote control commands that described client sends.
2. method according to claim 1, is characterized in that, the connection between described first listening port and described virtual switch is long connection; Remain connection status in the life cycle that described length is connected to the virtual switch of its correspondence always.
3. method according to claim 1, is characterized in that, described method also comprises:
After connection between arbitrary virtual switch and described first listening port disconnects, according to the connection establishment request that this virtual switch is initiated within a preset time interval again, re-establish this connection.
4. a long-range control method for virtual switch, is applied to client, it is characterized in that, the method comprises:
When receiving the remote control commands for object virtual switch of user's input, at local boot port listening service;
After described port listening service has started, the second listening port enabled in advance with described cloud management platform connects, and the port numbers of the 3rd listening port of being enabled by described port listening service by this connection and the IP address of object virtual switch send to described cloud management platform, to make described cloud management platform, the port numbers of described 3rd listening port are transmitted to described object virtual switch;
The control connection between described object virtual switch is set up in the control connection request of setting up that the described object virtual switch received based on described 3rd listening port is initiated, and described remote control commands is sent to described object virtual switch by this control connection.
5. method according to claim 4, is characterized in that, described method also comprises:
When described remote control commands sends to described object virtual switch by described control connection, and after receiving the execution result of described object virtual switch, close the described port listening service started, and discharge the control connection between described 3rd listening port and described object virtual switch.
6. the remote control of a virtual switch, be applied to cloud management platform, described cloud management platform enables the first listening port and the second listening port in advance, the connection establishment request that wherein said first listening port is initiated for receiving virtual switch, the connection establishment request that described second listening port is initiated for receiving client, it is characterized in that, this device comprises:
Setting up module, for being connected by described first listening port object virtual switch, and preserving the mapping relations between connection and the IP address of described object virtual switch set up in this locality;
Receiver module, for being connected by described second listening port and client, and receives the port numbers of the 3rd listening port of enabling in its this locality and the IP address of object virtual switch of the transmission of described client based on this connection;
Forwarding module, the connection corresponding with the IP address of the described object virtual switch received is obtained for inquiring about described mapping relations, and by this connection, the port numbers of described 3rd listening port is transmitted to described object virtual switch, to make described object virtual switch initiate to set up control connection to described client based on the port numbers of described 3rd listening port, and the control connection passing through to have set up receives the remote control commands that described client sends.
7. device according to claim 6, is characterized in that, the connection between described first listening port and described virtual switch is long connection; Remain connection status in the life cycle that described length is connected to the virtual switch of its correspondence always.
8. device according to claim 6, is characterized in that, described module of setting up is further used for:
After connection between arbitrary virtual switch and described first listening port disconnects, according to the connection establishment request that this virtual switch is initiated within a preset time interval again, re-establish this connection.
9. a remote control for virtual switch, is applied to client, it is characterized in that, this device comprises:
Start module, for when receiving the remote control commands for object virtual switch of user's input, at local boot port listening service;
First sending module, for after described port listening service has started, the second listening port enabled in advance with described cloud management platform connects, and the port numbers of the 3rd listening port of being enabled by described port listening service by this connection and the IP address of object virtual switch send to described cloud management platform, to make described cloud management platform, the port numbers of described 3rd listening port are transmitted to described object virtual switch;
Second sending module, the control connection initiated for the described object virtual switch received based on described 3rd listening port sets up the control connection of asking between foundation with described object virtual switch, and described remote control commands is sent to described object virtual switch by this control connection.
10. device according to claim 9, is characterized in that, described device also comprises:
Closing module, for after described remote control commands sends to described object virtual switch based on described control connection, close the described port listening service started, and discharge the control connection between described 3rd listening port and described object virtual switch.
CN201510479116.2A 2015-08-06 2015-08-06 The long-range control method and device of virtual switch Active CN105208072B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201510479116.2A CN105208072B (en) 2015-08-06 2015-08-06 The long-range control method and device of virtual switch

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201510479116.2A CN105208072B (en) 2015-08-06 2015-08-06 The long-range control method and device of virtual switch

Publications (2)

Publication Number Publication Date
CN105208072A true CN105208072A (en) 2015-12-30
CN105208072B CN105208072B (en) 2019-09-06

Family

ID=54955498

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201510479116.2A Active CN105208072B (en) 2015-08-06 2015-08-06 The long-range control method and device of virtual switch

Country Status (1)

Country Link
CN (1) CN105208072B (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112913196A (en) * 2018-10-30 2021-06-04 慧与发展有限责任合伙企业 Software defined wide area network uplink selection with virtual IP addresses for cloud services
CN116074227A (en) * 2022-11-09 2023-05-05 国网重庆市电力公司电力科学研究院 Multi-power system testing method based on virtualization platform
WO2024067882A1 (en) * 2022-09-29 2024-04-04 Wuhan United Imaging Healthcare Co., Ltd. Methods, systems, and devices for data transmission

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102104588A (en) * 2009-12-18 2011-06-22 国基电子(上海)有限公司 Multimedia terminal adapter and remote connection method thereof
CN102833323A (en) * 2012-08-14 2012-12-19 新浪网技术(中国)有限公司 Method and system for remote control of controlled terminal by server
CN103888511A (en) * 2014-02-20 2014-06-25 北京哈工大计算机网络与信息安全技术研究中心 Remote access control method based on dynamic proxy
CN104811478A (en) * 2015-03-27 2015-07-29 上海斐讯数据通信技术有限公司 Remote control system and method of wireless terminal equipment

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102104588A (en) * 2009-12-18 2011-06-22 国基电子(上海)有限公司 Multimedia terminal adapter and remote connection method thereof
CN102833323A (en) * 2012-08-14 2012-12-19 新浪网技术(中国)有限公司 Method and system for remote control of controlled terminal by server
CN103888511A (en) * 2014-02-20 2014-06-25 北京哈工大计算机网络与信息安全技术研究中心 Remote access control method based on dynamic proxy
CN104811478A (en) * 2015-03-27 2015-07-29 上海斐讯数据通信技术有限公司 Remote control system and method of wireless terminal equipment

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112913196A (en) * 2018-10-30 2021-06-04 慧与发展有限责任合伙企业 Software defined wide area network uplink selection with virtual IP addresses for cloud services
CN112913196B (en) * 2018-10-30 2023-06-06 慧与发展有限责任合伙企业 Software-defined wide area network uplink selection with virtual IP addresses for cloud services
WO2024067882A1 (en) * 2022-09-29 2024-04-04 Wuhan United Imaging Healthcare Co., Ltd. Methods, systems, and devices for data transmission
CN116074227A (en) * 2022-11-09 2023-05-05 国网重庆市电力公司电力科学研究院 Multi-power system testing method based on virtualization platform
CN116074227B (en) * 2022-11-09 2024-05-14 国网重庆市电力公司电力科学研究院 Multi-power system testing method based on virtualization platform

Also Published As

Publication number Publication date
CN105208072B (en) 2019-09-06

Similar Documents

Publication Publication Date Title
US10802906B2 (en) Monitoring method and apparatus of server, and storage medium
US11075821B2 (en) Method and apparatus for managing field device based on cloud server
US9391869B2 (en) Virtual network prototyping environment
CN109474936B (en) Internet of things communication method and system applied among multiple lora gateways
KR101979362B1 (en) Method for upgrading virtualized network function and network function virtualization orchestrator
CN107544841B (en) Virtual machine live migration method and system
US20180210752A1 (en) Accelerator virtualization method and apparatus, and centralized resource manager
GB2462160A (en) A distributed server system includes a table indicating communication relationships between various service programs
EP3261299A1 (en) Method and apparatus for establishing network service instance
CN104580029A (en) Address distribution method and device
CN105208072A (en) Remote control method and device of virtual switch
CN112667293B (en) Method, device and storage medium for deploying operating system
EP3439249A1 (en) Network system, management method and device for same, and server
CN114153607A (en) Cross-node edge computing load balancing method, device and readable storage medium
CN108134711B (en) Method for testing terminal APP, simulation household appliance system and storage medium
CN105827496A (en) Method and apparatus for managing PE device
CN103138961B (en) server control method, controlled server and central control server
CN112954770A (en) Device binding method and device, storage medium and electronic device
KR20150088462A (en) Method for linking network device in cloud environment and apparatus therefor
CN104811345A (en) Internet service dial test method, correlation devices and system
KR101883712B1 (en) Method, apparatus and computer program for managing a network function virtualization system
US11924300B2 (en) Methods for controlling a multi-access edge computing network
CN104468696A (en) Method, server and device for performing point-to-point connection
US11604670B2 (en) Virtual machine live migration method, apparatus, and system
CN109962788B (en) Multi-controller scheduling method, device and system and computer readable storage medium

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant